Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.71% | — | Withsecure Client SecurityAIWithsecure Server SecurityAIWithsecure Email AND Server SecurityAIWithsecure Elements Endpoint ProtectionAI+5 | 26/2/2024 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,… | |
| Modificada | Media (6.1) | 0.47% | — | Zalify Easy Email | 9/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher claims issue is present in all versions prior and later than tested version. | |
| Modificada | Media (6.7) | 0.17% | — | Withsecure Client SecurityWithsecure Server SecurityWithsecure Email AND Server SecurityWithsecure Elements Endpoint Protection | 8/2/2024 | 17/6/2026 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later. | |
| Modificada | Alta (7.2) | 1.2% | 💥 PoC | Remyandrade Login System With Email Verification | 29/1/2024 | 17/6/2026 | Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter. | |
| Modificada | Media (4.8) | 0.40% | — | Benaceur-php Restrict Usernames Emails Characters | 29/1/2024 | 17/6/2026 | The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (7.5) | 1.2% | — | Ypopsemail Ypops! | 29/1/2024 | 17/6/2026 | The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558. | |
| Modificada | Media (6.5) | 0.40% | — | Zorem Sales Report Email FOR Woocommerce | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8. | |
| Modificada | Media (5.4) | 0.40% | — | Onlineoptimisation Email Encoder | 11/1/2024 | 22/7/2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's eeb_mailto shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Crítica (9.8) | 0.71% | 💥 PoC | Cisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware | 10/1/2024 | 17/6/2026 | Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | |
| Modificada | Crítica (9.8) | 0.57% | — | Soxft Timemail | 9/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this… | |
| Modificada | Media (6.1) | 0.44% | — | I13websolution Email Subscription Popup | 8/1/2024 | 17/6/2026 | The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.3) | 0.43% | — | Sumanbhattarai Send Users Email | 5/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3. | |
| Modificada | Baja (3.3) | 0.20% | — | Samsung Email | 4/1/2024 | 17/6/2026 | Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information. | |
| Modificada | Media (4.8) | 0.33% | — | Zerobounce Email Verification & Validation | 29/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZeroBounce ZeroBounce Email Verification & Validation allows Stored XSS.This issue affects ZeroBounce Email Verification & Validation: from n/a through 1.0.11. | |
| Modificada | Crítica (9.8) | 45% | 💥 Exploit | Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+1 | 24/12/2023 | 17/6/2026 | Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic. | |
| Modificada | Alta (7.5) | 0.55% | — | Winwar WP Email Capture | 21/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10. | |
| Modificada | Media (5.4) | 0.40% | — | Tillkruss Email Address Encoder | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Till Krüss Email Address Encoder allows Stored XSS.This issue affects Email Address Encoder: from n/a through 1.0.22. | |
| Modificada | Media (4.8) | 0.46% | — | Codepeople Contact Form Email | 11/12/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.37% | — | I13websolution Email Subscription Popup | 6/12/2023 | 17/6/2026 | The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (5.3) | 0.62% | — | Gopiplus Email Download Link | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7. | |
| Modificada | Alta (7.5) | 0.67% | — | Gopiplus Email Posts TO Subscribers | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts to subscribers: from n/a through 6.2. | |
| Modificada | Media (6.1) | 0.43% | — | Sophos Email Appliance | 30/11/2023 | 17/6/2026 | A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4. | |
| Modificada | Alta (7.5) | 0.70% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Media (5.3) | 0.61% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Alta (7.5) | 0.55% | — | Omnisend Email Marketing FOR Woocommerce | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8. |